What it is
DKIM (DomainKeys Identified Mail) attaches a cryptographic signature to outbound mail that receivers verify against a public key published in DNS. Without DKIM, DMARC alignment can only rely on SPF, which fails on legitimate forwarded mail and gets brittle under any mail-flow change (new marketing platform, new e-sign vendor, forwarded newsletters).
Why it matters
Attackers rarely attack DKIM directly, they attack its absence. A domain with SPF-only alignment produces intermittent DMARC failures on legitimate mail, which pressures the domain owner to set p=none and keep it there. That permissive posture is what the attacker actually wants.
How anyone can check it
Send yourself an email and view its headers. Look for dkim=pass and your own domain after d=.
Remediation direction
Enable DKIM signing on every legitimate sender (Google Workspace, Microsoft 365, marketing platform, ATS, e-sign vendor) with 2048-bit keys. Publish each selector at <selector>._domainkey.<domain>. Verify with a DMARC aggregate report review after two weeks.
LeakTrace does not perform the fix. In an assessment, every finding carries a step-by-step remediation for the firm’s IT provider.